Courseiva

AZ-305 Practice Question: Design identity, governance, and monitoring solutions

A company wants workload deployments to access Azure resources without storing client secrets in CI/CD variables. The pipeline runs from GitHub Actions. Which identity design should be used?

⚠ Common exam trap

Test-takers frequently choose a long-lived client secret (Option D) thinking it is the standard way to authenticate, overlooking the requirement to avoid storing secrets and the modern OIDC-based federation approach.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Workload identity federation with Microsoft Entra ID

Workload identity federation with Microsoft Entra ID allows GitHub Actions to exchange an OpenID Connect (OIDC) token for an Azure access token, eliminating the need to store client secrets in CI/CD variables. This design uses short-lived tokens and federated identity credentials, aligning with the principle of zero-trust and secretless authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A shared user account with MFA disabled

    Why it's wrong here

    Using a shared user account with MFA disabled is a classic anti-pattern: user identities are designed for interactive human login, not automated workloads, and a shared account provides no accountability for individual actions. Because no MFA protects the account, a single leaked password gives total access, and replicating that shared credential into deployment pipelines increases the blast radius. Workload identity federation instead uses a distinct non-human identity that is trusted without static credentials and can be scoped with granular permissions.

  • ✗

    A storage account access key

    Why it's wrong here

    A storage account access key authenticates only against Azure Blob/File/Queue/Table data planes, so it cannot obtain OAuth tokens for Microsoft Entra ID-protected services such as Microsoft Graph, ARM, or Key Vault data plane. The key is an all-powerful, long-lived shared secret that grants full access to the storage account (including key management), making rotating and securing it a major operational burden. Even for storage scenarios, managed identities or Entra roles should be preferred; for general workload access, a workload identity federation token is required.

  • ✓

    Workload identity federation with Microsoft Entra ID

    Why this is correct

    Workload identity federation with Microsoft Entra ID lets an external workload (for example, a GitHub Actions job or a Kubernetes pod) present a token from its own trusted identity provider to Entra ID in exchange for an Entra access token. This uses OAuth 2.0 client credentials grant flow with no client secret, because the federated credential defines trust by issuer, subject, and audience. The resulting short-lived tokens can be scoped to Azure resources or Microsoft Graph, eliminating long-lived secrets and enabling automated rotation through the source identity provider.

  • ✗

    A long-lived app registration client secret

    Why it's wrong here

    An app registration client secret, even one with a long expiration, is a static shared secret that must be stored in code, build scripts, or vaults; anyone who extracts it can authenticate as the service principal until it expires or is rotated. Long-lived secrets are operationally risky because rotation is often forgotten, and unlike workload identity federation, they are not tied to an ephemeral source token from the workload's own provider. While service principal secrets can technically request Entra tokens, they are an outdated pattern that fails to provide the zero-lifetime-secret benefit of federated workload identity.

About these practice questions

Courseiva writes every AZ-305 question from scratch — 795 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This AZ-305 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-305 exam.